AI developers targeted via trojanized GitHub repositories Netskope Threat Labs reported that cybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, shifting from the ClickFix social engineering trick to trojanized repositories. The campaign, first reported in April 2026, targets developers by impersonating legitimate projects to deliver the Windows-based MaaS infostealer. Cybercriminals are cloning popular GitHub repositories for AI tools and developer resources to distribute an infostealer, according to Netskope Threat Labs. Source: Netskope Netskope came across the campaign while tracking a Windows-based MaaS infostealer, first reported in April 2026, that was spread through the ClickFix social engineering trick. Continuing to follow the operation, the researchers found that the group behind it had shifted its delivery method, now pushing payloads through impersonated GitHub repositories hosting popular … More https://www.helpnetsecurity.com/2026/08/04/developers-github-fake-ai-tools-infostealer/ The post AI developers targeted via trojanized GitHub repositories https://www.helpnetsecurity.com/2026/08/04/developers-github-fake-ai-tools-infostealer/ appeared first on Help Net Security https://www.helpnetsecurity.com .